Skip to main content

Boteraser | Website and Server Security Solutions

BackStreet

Bot User-Agent: backstreet

⚠️ Overview

BackStreet is a malicious botnet discovered in 2021 by security researchers at Qihoo 360's Netlab, targeting Linux-based IoT devices and web servers. It is a Mirai variant that shares code with the original Mirai botnet but introduces enhanced propagation techniques and a modular architecture for launching DDoS attacks.

🔧 Technical Capabilities

BackStreet scans the internet for exposed devices running Telnet (port 23) or SSH (port 22) with default or weak credentials, using a built-in dictionary of over 100 common username/password pairs. Once compromised, the bot downloads a loader component from a remote command-and-control server, which then deploys attack modules capable of launching TCP SYN floods, UDP amplification floods (using DNS, NTP, and SSDP protocols), and HTTP GET/POST floods for Layer 7 DDoS attacks. It also includes a self-propagating worm module that scans random IPv4 addresses to find new victims, and can disable competing malware by killing processes and deleting files. BackStreet uses an encrypted communication channel with its C2 to evade detection, and updates its configuration dynamically via base64-encoded commands. The botnet specifically targets devices running Linux on ARM, MIPS, and x86 architectures, often exploiting unpatched vulnerabilities such as CVE-2017-17215 (Huawei HG532 router remote code execution).

📜 History & Notable Incidents

First identified in February 2021 by Netlab, BackStreet was observed attacking multiple targets in Asia and Europe, with peak infected node counts exceeding 10,000. In April 2021, the botnet was linked to a series of DDoS attacks against gaming servers and cryptocurrency mining pools, generating traffic volumes up to 200 Gbps. The malware's codebase was later partially published on a hacking forum, leading to multiple copycat variants. No CVE entries are directly assigned to BackStreet itself, but it exploits existing CVEs like CVE-2017-17215.

🔍 Detection Indicators

Traffic to unusual IP addresses on ports 4433 or 8080 for C2 communication, combined with a high volume of outbound SYN packets to random IPs on ports 23 and 22, are key indicators. The malware uses a unique User-Agent string for its HTTP flood modules: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36 (spoofed but identifiable). Behavioral fingerprints include rapid Telnet login attempts (over 100 per second) and the creation of files named .backstreet or .ssh_backstreet in /tmp.

☠️ Risk & Impact

Infected devices are fully controlled by the attacker, becoming part of a DDoS botnet that can disrupt critical online services. The worm-like propagation can quickly compromise all vulnerable devices on a local network, leading to data exfiltration of credentials and sensitive configurations stored on IoT devices. Successful attacks can cause extended downtime for websites, gaming platforms, and industrial control systems.

🛡️ Mitigation

BackStreet is blocked immediately on detection because its autonomous self-propagation and aggressive DDoS capabilities pose an immediate threat to network availability and device integrity. Any observed traffic matching its C2 patterns or brute-force activities triggers automatic firewall blacklisting to prevent further spread.

⚠️

Your Site May Be Hemorrhaging Revenue to Bots

Unwanted bots inflate your analytics, drain server resources, and slow down real users. Check if your site is affected — completely free.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.